Loom appears to be a coherent, transparently published new package rather than an abandoned or poorly backed release: the repository matches the package, the README documents usage, the repository contains tests, the package has a license, dependency scope is small, and its workflow uses read-only permissions without detected dangerous patterns. However, this is a very early v0.1.0 release with only one release, no established release cadence, no observed three-month commit activity, and no security policy. Those limitations make its long-term maintenance and maturity unproven, so it is usable with normal caution rather than yet representing a strongly established dependency.
72%
Total Score
83
100
89
88
The package is brand new, with one release and an age of 0 days, so there is no demonstrated release cadence or maintenance track record yet.
There were zero commits and zero active maintainers in the measured three-month window. Because the package was released only hours before collection, this is not evidence of abandonment, but it leaves ongoing maintenance unproven.
No security policy was found, which is a transparency and vulnerability-reporting gap, although the package's very small and newly published scope limits how strongly this weighs.
The latest version is v0.1.0 and is not a stable major release, which indicates an immature API and a higher chance of breaking changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.2 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.